Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.

Comments:EventID.Net
This issue can occur when the user account becomes corrupted. See ME307234 for details.

If the solutions provided by Microsoft are not working for you, see the link to "Windows Networking Article" for information on solving this issue.

Also see the links to "JSI Tip 2526" and "JSI Tip 2194" for additional information on this event.

EventID.Net
For a general approach in troubleshooting this event see: ME266416 (link below). As per Microsoft: "The AutoDiscovery/AutoPurge (ADAP) process is responsible for collecting and maintaining performance counter objects in WMI that are registered on the computer. The ADAP process starts when the WinMgmt service is started or when you install or uninstall the performance libraries, which contain the performance counters, by using either the Lodctr or Unlodctr utilities. Although the events are logged, the counters are still available."

This event may also be generated during startup as the counters are slow to respond due to other activities that take place on a starting computer. The ME266416 gives you the registry key to add in order to increase the timeout period during startup. Some application specific causes can be found by following the links.

EventID.Net
Please see a fix as per ME255629: "a problem in the WMI Performance Library dredger. In certain situations, the dredger incorrectly determines that a library is invalid even though the counter works correctly".
x
1